Featured Job

Product Security Engineer

San Francisco, CA Full-time Remote $175k — $275k per year 10/01/2026 Job ID: 000309
Apply Now
Risk Assessment Secure Design Code Review Penetration Testing Static Analysis

Summary

What you’ll impact

Our organization is seeking a security engineer to lead secure design, build secure-by-default systems, and perform offensive security testing while collaborating closely with engineering teams. The role involves improving security tooling, operating the responsible disclosure program, and engaging directly with customers to enhance trust and product security.

Responsibilities

What you'll do

  • Lead secure design efforts. Partner with engineering teams on secure design and code reviews. Identify and prioritize risks early in the product lifecycle.
  • Build secure by default systems. Develop paved paths that systemically reduce risk and make secure development the easiest path for engineers.
  • Perform offensive security testing. Conduct penetration tests and code audits on new and existing products from an adversarial lens.
  • Improve our security tooling. Integrate and improve our static analysis, supply chain security, and vulnerability management capabilities across engineering pipelines.
  • Operate our responsible disclosure program. Run and improve our program by furthering automation, validating submissions, and coordinating remediation.
  • Improve our products. Write and ship code to remediate vulnerabilities in production systems and improve the security posture of WorkOS products.
  • Work directly with customers. Help build our customers' trust by directly engaging with their security-related questions and concerns.

Requirements

What you’ll bring

  • 5+ years of experience in a security engineering or security-focused software engineering role.
  • Ability to execute across a wide range of security functions such as security assessments, penetration testing, responsible disclosure, security tooling integration, etc.
  • Familiarity with and experience using common industry tooling.
  • Proven ability to identify vulnerabilities in software, demonstrated through CVEs, bug bounty, blog posts, or prior work experience.
  • Strong written and verbal communication skills, particularly in partnering with engineering teams.
  • Comfortable reading and writing code, and able to effectively leverage AI during the process.
  • Bonus: Experience in the authentication and identity domain.
  • Bonus: Experience writing production level code, especially developing security features.

Ready to Move Forward?

Apply now and our recruiting team will reach out with next steps, interview guidance, and client insights tailored to this role.